Impact
The Desktop Window Manager contains a use‑after‑free flaw that can be triggered by a local user who can execute code that interacts with DWM interfaces. This memory corruption allows the attacker to gain elevated privileges on the Windows 11 26H1 system, enabling arbitrary code execution at a higher access level and potentially compromising the entire machine.
Affected Systems
Microsoft Windows 11 version 26H1 is identified as affected. No other vendors or versions appear in the CNA data.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability in the high‑severity range, while the EPSS score of less than 1% indicates that exploitation attempts are currently rare. The flaw is not listed in CISA’s KEV catalog. Attackers would need local access to trigger the faulty use‑after‑free in DWM, typically by running malicious code that calls DWM functions. The low exploitation probability does not negate the need for patching, as the potential impact of privilege escalation is severe.
OpenCVE Enrichment